Missing Authorization in Keycloak - CVE-2026-18571
Published: August 2, 2026 / Updated: September 5, 2026
Vulnerability details
The vulnerability allows a remote user to grant newly created users elevated privileges.
The vulnerability exists due to missing authorization in the user creation component when Fine-Grained Admin Permissions V2 is enabled. A remote privileged user can create users and add them to groups they are not authorized to manage to grant newly created users elevated privileges.